Sub-processors
The suppliers who process personal data for rTraining, what each one does, what it is sent, and how organisation customers are told of a change.
These are the companies that process personal data for rTraining. For each one, this page says what it does, what it is sent, and where it processes it. Where an organisation has enrolled its staff and we act as its processor, these are our sub-processors under the data processing agreement.
The list is written from what the application actually calls. A supplier that is not on it is not sent personal data by rTraining.
The list
Supabase
- What it does: the database, sign-in and file storage. It holds accounts, training records, certificates, attempts, Ask conversations, the email log and uploaded files.
- What it is sent: everything the platform stores.
- Where: London, United Kingdom (AWS eu-west-2).
Vercel
- What it does: hosts and serves the website and runs the scheduled jobs, such as reminders and the weekly renewals report. It tells us which country a first visit appears to come from, so that the right region and currency are shown.
- What it is sent: every request to the site passes through it, including the pages you ask for and your connection's address.
- Where: the application runs in Vercel's London region (lhr1). Static files are served from Vercel's edge network nearest the visitor, which can be outside the UK, and Vercel may process request logs outside the UK, including in the United States.
Stripe
- What it does: takes card payments, runs subscriptions and holds the billing record for each customer.
- What it is sent: your email address, what you bought and the price, and for an organisation, its name. What you type into the payment form, including your card details, goes straight to Stripe and never reaches us.
- Role: Stripe is a controller in its own right for card data and fraud checks.
- Where: the United Kingdom, the European Union and the United States.
PostHog
- What it does: product analytics, recordings of visits to the public site, and error reports.
- What it is sent: only if you accept measurement in the cookie banner, the pages you visit and what you click, identified by an opaque user id and never by name or email. On the public site, sign-in, checkout and sign-up, a recording of the visit with everything you type masked. Browser errors, with email addresses and ids removed. Whatever you choose, errors on our servers, with the account's internal id where somebody was signed in, and no name, email address, cookies or headers. No assessment data is ever sent. For learners an organisation enrolled, no identity and nothing that persists between visits, unless that organisation's agreement expressly allows it.
- Where: European Union.
OpenAI
- What it does: answers questions in Ask and the section tutor, checks those questions for abuse, and gives each new Ask chat a short name. For our own course production, it generates course cover images and transcribes each narration recording so that we can check it says what the course text says.
- What it is sent: for Ask, the learner's question, their last three questions and answers, the text of the courses they hold, matching help pages and, on the Ask page, a summary of their own account: plan, courses, progress, certificate and renewal dates, and due dates. Never their name, email address, employer or any identifier, and nothing from an assessment. To name a chat, the first question and the start of its answer, once. For cover images, our own descriptions of a course. For transcription, audio we generated from our own course text. Neither of those carries any learner data.
- What it keeps: we use OpenAI's API with storage switched off (
store: false), and under OpenAI's API terms it does not use data sent through the API to train its models. OpenAI may keep API data for a limited period to detect abuse, as its API terms allow, and then deletes it. - Where: the United States.
ElevenLabs
- What it does: generates the narration of each section and the read-aloud of assessment questions.
- What it is sent: course text and question text, when a course is prepared. No learner data.
- Where: the United States and the European Union.
Anthropic
- What it does: its Claude models draft course sections and assessment questions for our authors, and our staff use Claude through a connector to work on draft courses.
- What it is sent: the sources and plan for a course. Through the connector, the names, qualifications, registration numbers and email addresses of the authors and reviewers on our register. No learner data.
- Where: the United States.
Microsoft
- What it does: Microsoft 365 sends every email the platform sends, from
training@rtriibe.com, through Microsoft Graph: certificates, share links, invitations, assignments and reminders, order and billing emails, renewal reminders, and alerts and reports to our own staff, including the weekly renewals report. A copy of each email is kept in that mailbox's sent items for up to 12 months. Sign-in links are sent by Supabase until our sign-in emails are moved on to Microsoft 365 as well. - What it is sent: the recipient's address and the email itself.
- Where: Microsoft's data centres, which may be outside the United Kingdom, including in the European Union and the United States.
Not sub-processors
- Fonts are bundled with the site when it is built. No request is made to a font service when you visit.
- We do not use advertising networks, social media pixels or embedded content from other sites.
Changes to this list
We will tell organisation customers at least 30 days before adding or replacing a sub-processor, and an organisation may object on reasonable data protection grounds, as the data processing agreement sets out. This page is updated when the list changes.
Where a provider handles personal data outside the UK and the country does not have UK adequacy, the transfer is covered by the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, or by the UK Extension to the EU-US Data Privacy Framework where the provider is certified, and we assess the risk of each transfer before we make it.